Showing results for 
Search instead for 
Did you mean: 
Level 7
Report Inappropriate Content
Message 1 of 1

Dashboard False Positive Tuning

My objective is to tune a dashboard that I have created for certain false positive conditions so the events are no longer visible from the view.  For example when using the Normalized Dashboard I want to add a filter to drop events from a certain ip address such as when the destination port is tcp 80.  I can easily add a filter for each of the individual conditions to filter out all events from or port 80, but I am not sure how to filter them out when the combination occurs.  Does anybody know if this is possible?


More McAfee Tools to Help You
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • Visit: Business Service Portal
  • More: Search Knowledge Articles
  • ePolicy Orchestrator Support

    • Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center